MAL-2026-823
Dashboard / Malicious Package / MAL-2026-823
MAL-2026-823
Published: 10 Feb 2026Last Modified: 10 Feb 2026
Summary: Malicious code in ntoutils (PyPI)
Details: Source: kam193 (15b6e8b1974bbd5ee6ee5e5abe0619080d87644b200fd8fc410f70a2f23213ff) Importing the module downloads and runs a remote executable identified as malware Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-ntoutils Reasons (based on the campaign): - Downloads and executes a remote executable. - malware
References: https://www.virustotal.com/gui/file-analysis/OWRkY2RkMzE3MTcyYTQ3NWRkNGVkNTIyYWE3M2E1ZGE6MTc3MDcwODgxNg==/summary, https://bad-packages.kam193.eu/pypi/package/ntoutils
Affected packages
Package
Name: ntoutils
Purl: pkg:pypi/ntoutils
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
1.3.1
1.3.2
